Send cert alerts to ntfy over loopback
The script posted alerts to https://ntfy.silverwal.com/certbot, which is served by the same nginx whose certificates it monitors. A TLS failure on this host would make curl -fsS fail verification and drop the alert describing that failure, leaving only a line in a log nobody reads. ntfy is already bound to 127.0.0.1:2586, so post there instead.
This commit is contained in:
@@ -33,7 +33,7 @@ sudo install -m 0755 scripts/check-cert-expiry.sh /opt/scripts/check-cert-expiry
|
|||||||
```bash
|
```bash
|
||||||
CERT_DIR=/etc/letsencrypt/live
|
CERT_DIR=/etc/letsencrypt/live
|
||||||
EXPIRY_DAYS=14
|
EXPIRY_DAYS=14
|
||||||
NTFY_URL=https://ntfy.silverwal.com/certbot
|
NTFY_URL=http://127.0.0.1:2586/certbot
|
||||||
ALERT_ON_NO_CERTS=true
|
ALERT_ON_NO_CERTS=true
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -64,6 +64,13 @@ ntfy is a good default for this server because it is already self-hosted, simple
|
|||||||
to call from shell scripts, and supports useful alert metadata such as title,
|
to call from shell scripts, and supports useful alert metadata such as title,
|
||||||
priority, and tags.
|
priority, and tags.
|
||||||
|
|
||||||
|
Alerts go to ntfy over `http://127.0.0.1:2586` rather than the public
|
||||||
|
`https://ntfy.silverwal.com` URL. The public URL is served by the same nginx
|
||||||
|
whose certificates this script watches, so an expired or broken certificate on
|
||||||
|
this host would fail curl's TLS verification and silently drop the very alert
|
||||||
|
that reports it. The loopback address removes DNS, nginx, and TLS from the
|
||||||
|
alerting path.
|
||||||
|
|
||||||
For jobs where silence is also a failure, pair ntfy with a dead man's switch such
|
For jobs where silence is also a failure, pair ntfy with a dead man's switch such
|
||||||
as Healthchecks. ntfy tells you what the script found; Healthchecks tells you when
|
as Healthchecks. ntfy tells you what the script found; Healthchecks tells you when
|
||||||
the script did not run at all.
|
the script did not run at all.
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ set -uo pipefail
|
|||||||
|
|
||||||
CERT_DIR="${CERT_DIR:-/etc/letsencrypt/live}"
|
CERT_DIR="${CERT_DIR:-/etc/letsencrypt/live}"
|
||||||
EXPIRY_DAYS="${EXPIRY_DAYS:-14}"
|
EXPIRY_DAYS="${EXPIRY_DAYS:-14}"
|
||||||
NTFY_URL="${NTFY_URL:-https://ntfy.silverwal.com/certbot}"
|
NTFY_URL="${NTFY_URL:-http://127.0.0.1:2586/certbot}"
|
||||||
NTFY_TITLE="${NTFY_TITLE:-SSL certificate warning}"
|
NTFY_TITLE="${NTFY_TITLE:-SSL certificate warning}"
|
||||||
NTFY_PRIORITY="${NTFY_PRIORITY:-high}"
|
NTFY_PRIORITY="${NTFY_PRIORITY:-high}"
|
||||||
NTFY_TAGS="${NTFY_TAGS:-warning,lock}"
|
NTFY_TAGS="${NTFY_TAGS:-warning,lock}"
|
||||||
|
|||||||
Reference in New Issue
Block a user